Medterracbd.com is a browser hijacker that forcibly redirects your web searches and homepage settings to promote questionable CBD products and drive affiliate revenue. Unlike more severe threats like ransomware or banking trojans, this malware doesn't typically encrypt files or steal passwords directly, but it compromises your browsing experience, exposes you to potentially malicious advertising networks, and can serve as a gateway for additional unwanted software. Users typically encounter this hijacker bundled with free software downloads or disguised as a browser extension offering health-related content.

Medterracbd.com — cybersecurity illustration
Photo by AI25.Studio Studio on Pexels

Once installed, Medterracbd.com modifies browser settings across Chrome, Firefox, Edge, and Safari, making these changes difficult to reverse through normal means. The hijacker alters your default search engine, new tab page, and homepage to redirect through its own domains, collecting search data and browsing habits while subjecting you to a stream of sponsored links and advertisements. While not the most dangerous malware you might encounter, it represents a persistent nuisance that degrades system performance and privacy.

Think you're infected right now? Disconnect from the internet immediately if you're experiencing constant redirects or seeing Medterracbd.com pop up repeatedly. Don't enter passwords or financial information until the hijacker is removed. If you're uncomfortable performing manual removal, call Computer Repair Roswell at (770) 594-5208 — we handle browser hijacker removal same-day for Roswell-area residents.

Threat Profile

Attribute Details
Threat Family Browser Hijacker / Potentially Unwanted Program (PUP)
Aliases Medterracbd redirect, Medterracbd.com hijacker, CBD Search Redirect
Affected Platforms Windows 7/8/10/11, macOS 10.12+
Affected Browsers Google Chrome, Mozilla Firefox, Microsoft Edge, Safari
Distribution Methods Software bundling, fake browser updates, malicious extensions, torrent downloads
Persistence Mechanism Browser extension policies, scheduled tasks (Windows), LaunchAgents (macOS), modified browser shortcuts
Primary Capabilities Search redirection, homepage hijacking, new tab replacement, ad injection, data collection
Data Collection Search queries, browsing history, clicked links, device fingerprinting information
Typical Symptoms Unwanted redirects to Medterracbd.com, changed homepage/search engine, excessive CBD-related ads, slow browser performance
Network Behavior Connects to ad network domains, tracks clicks via redirect chains, communicates with affiliate tracking servers
Common File Locations Browser extension folders, %APPDATA% subfolders (Windows), ~/Library/Application Support (macOS)
Removal Difficulty Moderate — requires browser cleanup, extension removal, and detection of hidden persistence mechanisms

How It Spreads

Browser hijackers like Medterracbd.com rarely arrive through sophisticated exploits. Instead, they rely on social engineering and user inattention during software installation. The most common distribution vector is software bundling, where the hijacker components are packaged alongside legitimate free applications. When users rush through installer screens clicking "Next" repeatedly without reading the fine print, they inadvertently agree to install additional "recommended" software that includes the browser hijacker. These bundled installers often use deceptive interface designs, pre-checking optional software boxes or using confusing language to obscure what's actually being installed.

Fake browser update notifications represent another major distribution channel. Users visiting compromised or low-quality websites encounter pop-ups claiming their browser or Flash Player is out of date and needs immediate updating. These fake prompts display convincing graphics mimicking legitimate update screens, but clicking "Update Now" downloads the hijacker instead. Similarly, malicious browser extensions advertised as helpful tools for blocking ads, downloading videos, or accessing special content serve as delivery mechanisms. Once granted permissions during installation, these extensions can modify browser behavior extensively.

Additional distribution methods include:

  • Torrent and piracy sites: Cracked software downloads frequently carry bundled hijackers and PUPs as part of the "crack" package
  • Malvertising networks: Compromised advertisements on otherwise legitimate sites that trigger drive-by downloads or redirect to hijacker installation pages
  • Email attachments: Less common for this threat type, but document macros or executable attachments can deploy browser hijackers as secondary payloads
  • Compromised download mirrors: Third-party software download sites that inject hijackers into otherwise legitimate application installers
  • Search engine poisoning: Fake download sites ranking highly for popular software searches, offering installer packages pre-loaded with the hijacker

What It Does On Your Machine

Upon successful installation, Medterracbd.com immediately targets your web browsers' configuration files and settings. The hijacker modifies registry entries on Windows systems or preference files on macOS to change your default search provider, homepage, and new tab page to domains controlled by the threat actors. These changes override user preferences and resist normal attempts to revert them through browser settings. When you attempt to change your homepage back to Google or another preferred site, the hijacker's persistence mechanisms quickly restore the unwanted settings within minutes or after the next browser restart.

The hijacker establishes multiple persistence methods to survive removal attempts. On Windows, it commonly creates scheduled tasks that periodically check for and reinstall browser modifications. It may also modify browser shortcut files, adding target parameters that force the browser to load the hijacker's homepage regardless of settings. Browser extensions installed by Medterracbd.com often request administrator-level permissions or install via enterprise policies that prevent normal uninstallation. On macOS systems, launch agents and launch daemons ensure the hijacker components reload after system restarts.

From a functional standpoint, Medterracbd.com intercepts your search queries and browsing activity. When you type a search term into the address bar or search box, the hijacker routes that query through its own servers before eventually displaying results — often from a legitimate search engine like Bing or Google, but modified to include sponsored links at the top. This redirection chain serves multiple purposes: it generates affiliate revenue when you click on promoted links, it collects data about your search behavior and interests, and it exposes you to advertising networks that may themselves serve malicious content. The collected data typically includes search terms, clicked URLs, browser type and version, operating system, IP address, and general geographic location.

Beyond search redirection, the hijacker injects advertisements into web pages you visit and generates pop-ups promoting CBD products, health supplements, and other questionable merchandise. These injected ads can slow page loading times, consume bandwidth, and in some cases redirect to phishing sites or pages hosting additional malware. Users report decreased browser performance, increased memory consumption, and occasional browser crashes as the hijacker scripts run continuously in the background. While Medterracbd.com itself doesn't typically contain keylogging or banking trojan functionality, the advertising networks it connects to have delivered more serious threats in documented cases.

Typical Medterracbd.com Artifacts (Windows Example)
Browser Extension Paths: %LOCALAPPDATA%\Google\Chrome\User Data\Default\Extensions\\ %APPDATA%\Mozilla\Firefox\Profiles\.default\extensions\@medterracbd.xpi Scheduled Tasks: C:\Windows\System32\Tasks\MedterraCBDUpdate C:\Windows\System32\Tasks\BrowserHelper Registry Keys (Search Provider): HKCU\Software\Microsoft\Internet Explorer\SearchScopes\ HKCU\Software\Policies\Google\Chrome\DefaultSearchProviderSearchURL Modified Shortcuts (target parameter injection): "C:\Program Files\Google\Chrome\Application\chrome.exe" http://medterracbd.com Common Binary Locations: %APPDATA%\\service.exe %LOCALAPPDATA%\Temp\\installer.dll

Manual Removal — Step by Step

01

Disconnect from the Internet

Before beginning removal, disconnect your computer from the network by unplugging the ethernet cable or disabling Wi-Fi. This prevents the hijacker from communicating with command servers, downloading additional components, or re-establishing settings during the cleanup process. Work offline until removal is complete and verified.

02

Uninstall Suspicious Programs via Control Panel

Open Control Panel (Windows) or Applications folder (macOS) and examine recently installed programs. Look for unfamiliar applications installed around the time the redirects began, particularly those with generic names, publisher names you don't recognize, or install dates matching when problems started. Uninstall anything suspicious, including browser helper applications, toolbars, or programs related to CBD, shopping, or web optimization. On macOS, drag suspicious applications to Trash and empty it.

03

Remove Malicious Browser Extensions

Open each installed browser and navigate to the extensions/add-ons management page (chrome://extensions/, about:addons for Firefox, edge://extensions/ for Edge). Disable and remove any extensions you didn't intentionally install or don't recognize, paying special attention to those with excessive permissions like "read and change all your data on websites." If an extension refuses to uninstall or reappears immediately, the hijacker may have installed it via enterprise policy or administrator permissions — you'll need to address that in later steps.

04

Reset Browser Settings to Defaults

In Chrome, go to Settings → Reset settings → Restore settings to their original defaults. In Firefox, navigate to about:support and click "Refresh Firefox." In Edge, go to Settings → Reset settings → Restore settings to their default values. This process removes the hijacker's modifications to your homepage, search engine, and new tab page while preserving bookmarks and passwords. After resetting, manually configure your preferred homepage and search engine, then immediately check if the unwanted settings return — if they do, persistence mechanisms are still active.

05

Check and Repair Browser Shortcuts

Right-click on your browser shortcuts (desktop, taskbar, Start menu) and select Properties. Examine the "Target" field — it should contain only the path to the browser executable with no additional URLs or parameters. If you see a web address appended after the .exe path, delete everything after the closing quotation mark that follows chrome.exe, firefox.exe, or msedge.exe. Apply the changes and repeat for all browser shortcuts you use.

06

Delete Scheduled Tasks and Persistence Mechanisms

Open Task Scheduler (Windows) by typing "taskschd.msc" in the Run dialog, or examine LaunchAgents (macOS) in ~/Library/LaunchAgents/ and /Library/LaunchAgents/. Look for scheduled tasks with suspicious names, especially those running frequently or at startup, with generic names like "BrowserHelper," "Update," or random character strings. Delete tasks you don't recognize that were created recently. On macOS, move suspicious .plist files from LaunchAgents folders to Trash. Check the Startup folder in Windows (shell:startup) and remove unfamiliar items.

07

Manually Delete Hijacker Files and Folders

Navigate to %APPDATA%, %LOCALAPPDATA%, and %TEMP% on Windows (type these into Explorer's address bar) or ~/Library/Application Support/ on macOS. Sort by Date Modified to find recently created folders. Delete any suspicious folders created around infection time, particularly those with random-character names or containing executable files you don't recognize. Empty the Recycle Bin or Trash when complete. Be cautious not to delete legitimate application data — when in doubt, search online for the folder name before deleting.

08

Scan with Reputable Anti-Malware Software

Reconnect to the internet and download Malwarebytes Free or another reputable scanner if you don't already have one installed. Perform a full system scan to catch any components manual removal missed. Browser hijackers often install multiple related PUPs that work together, and automated scanners excel at detecting these families. Remove everything the scanner identifies, even if flagged as "low severity" — these bundled components often reinstall the hijacker if left behind.

09

Clear Browser Cache and Cookies

After removing the hijacker components, clear your browser's complete history, cache, and cookies. This eliminates any tracking cookies the hijacker installed and removes cached versions of hijacked pages. In Chrome, Edge, and Firefox, access this through Settings → Privacy and Security → Clear browsing data, selecting "All time" as the time range and checking all available categories including cached images, cookies, and site data.

10

Restart and Verify Clean System

Reboot your computer and test your browsers thoroughly. Verify that your chosen homepage loads correctly, searches use your preferred search engine without redirects, and new tabs open to your expected page. Visit a few common websites and confirm no unexpected pop-ups or injected advertisements appear. Monitor the system for 24-48 hours — if Medterracbd.com settings return or redirects resume, a persistence mechanism survived initial removal and requires deeper investigation.

Prevention

  1. Download software only from official sources: Use publishers' official websites or verified sources like Microsoft Store, Apple App Store, or reputable repositories. Avoid third-party download sites like Softonic, Download.com, or CNET Downloads that frequently bundle PUPs with legitimate software. When the official site is unclear, search for "[software name] official download" rather than clicking the first search result.
  2. Read installer screens carefully and choose custom installation: Never click through installer wizards on autopilot. Always select "Custom" or "Advanced" installation options instead of "Express" or "Recommended." Read each screen for pre-checked boxes offering additional software, browser toolbars, or homepage changes. Decline all optional offers that aren't the specific program you intended to install.
  3. Keep browsers and operating systems updated: Enable automatic updates for your operating system and web browsers. Security patches frequently address vulnerabilities that hijackers and malware exploit. An up-to-date system provides fewer attack surfaces for browser-based threats.
  4. Use browser security extensions: Install reputable ad blockers like uBlock Origin and consider malicious site blockers. These extensions can prevent many malvertising attacks and block connections to known hijacker domains before they load. Avoid sketchy "security" extensions that themselves function as hijackers.
  5. Be skeptical of update prompts on websites: Legitimate software updates occur through the application itself or your operating system's update mechanism — not through browser pop-ups. If a website claims your Flash Player, browser, or video player is out of date, close the tab and verify through the software's official update channel. Modern browsers update automatically without user intervention.
  6. Review browser extensions regularly: Audit your installed browser extensions monthly. Remove any you no longer use or don't remember installing. Each extension represents additional permissions and potential vulnerabilities. The fewer extensions you maintain, the smaller your attack surface.
  7. Maintain a reputable anti-malware solution: Keep real-time protection software running, even if it's just Windows Defender (which has improved dramatically in recent years). Schedule weekly scans and keep definitions updated. While anti-malware won't catch every PUP before installation, it provides a safety net for threats that slip through.
  8. Create separate user accounts for daily use: Run your computer with a standard user account rather than an administrator account for everyday browsing and work. Browser hijackers have more difficulty establishing system-level persistence without administrator privileges. Reserve the admin account for software installation and system maintenance.
Our 90-Day Guarantee: When Computer Repair Roswell removes malware from your system, we back our work with a 90-day warranty. If the same threat returns within 90 days of service, we'll remove it again at no additional charge. We don't just delete the visible infection — we hunt down persistence mechanisms, clean browsers completely, and verify your system is truly clean before returning it to you.

Bring It In

Browser hijackers like Medterracbd.com frustrate users precisely because they're designed to resist casual removal attempts. While the manual steps above work when followed carefully, many people find the hijacker returns days later because a hidden scheduled task or enterprise policy survived cleanup. At Computer Repair Roswell, we've removed hundreds of browser hijackers from Roswell-area computers, and we know exactly where these threats hide their persistence mechanisms. We use specialized tools to detect policy-based installations, hunt down modified registry entries that typical scans miss, and verify complete removal before returning your computer.

If you've spent hours fighting Medterracbd.com redirects or you simply want the confidence of professional removal, bring your computer to our Roswell shop or give us a call at (770) 594-5208. We handle most hijacker removals same-day, typically within 2-4 hours, and we'll explain what we found and how it got there so you can avoid reinfection. Our flat-rate malware removal service covers complete system cleanup, not just the immediate threat — if we find additional PUPs or security issues during the work, we address them as part of the service. We're located right here in Roswell, we've served this community for years, and we'll treat your computer with the same care we'd give our own family's machines.